How Zapret's Game Filter Mode Bypasses DPI for Games and UDP Applications

Zapret's Game Filter mode captures all TCP and UDP traffic on high-numbered ports (1024-65535) using WinDivert, forcing game traffic through a user-space filter that circumvents Deep Packet Inspection (DPI) by intercepting packets before the Windows networking stack processes them.

The Flowseal/zapret-discord-youtube repository provides a Windows implementation of the zapret DPI bypass tool, featuring a specialized Game Filter configuration designed specifically for UDP-heavy gaming applications. This mode enables the winws.exe binary to intercept dynamic high-port connections that traditional DPI systems often fail to inspect, effectively creating a transparent tunnel for game traffic.

What Is Game Filter Mode?

Game Filter is a traffic capture configuration managed through service.bat that directs the bypass engine to handle all connections on ephemeral ports. When activated, the script creates a persistence flag at utils\game_filter.enabled containing one of three values: all, tcp, or udp. These values determine whether the service intercepts both protocols or isolates a specific transport layer, with the configuration persisting across system restarts until explicitly disabled.

How Game Filter Bypasses DPI

The bypass mechanism operates through three coordinated stages that redirect packets around network inspection points.

Port Range Selection

The activation logic resides in service.bat within the Game Switch block (lines 71-83 and 91-119). When a user selects Game Filter from the interactive menu, the script evaluates the choice and sets environment variables accordingly:

  • Mode all: Sets GameFilter=1024-65535 for both TCP and UDP
  • Mode tcp: Sets GameFilterTCP=1024-65535 for TCP only
  • Mode udp: Sets GameFilterUDP=1024-65535 for UDP only

These variables are stored in utils\game_filter.enabled and parsed during service initialization to determine which port ranges WinDivert should capture.

Argument Injection

During service installation (service_install section, lines 302-308), service.bat performs placeholder substitution on the strategy file. The script replaces %%GameFilter%%, %%GameFilterTCP%%, and %%GameFilterUDP%% tokens with the numeric ranges defined in the previous stage. The resulting arguments are appended to the service creation command:

sc create zapret binPath= "\"%BIN_PATH%winws.exe\" !ARGS!" start= auto

This injection occurs at lines 49-52 of service.bat, ensuring the WinDivert driver captures the specified port ranges immediately upon service startup.

WinDivert Packet Interception

The winws.exe binary utilizes the WinDivert driver to operate at the Windows filtering platform layer, intercepting raw packets before they reach the standard networking stack. By supplying the high-port range arguments (1024-65535), the tool captures all traffic on dynamic ports commonly used by online games. Because DPI implementations typically monitor standard ports (80, 443) and struggle with high-volume UDP streams, diverting these packets through user-space processing effectively removes them from the ISP's inspection path.

Enabling Game Filter Mode

Activation requires running service.bat and navigating the interactive menu system defined at lines 94-98, with the game_switch routine handling input at lines 443-473.

  1. Execute service.bat and select 4. Game Filter
  2. Choose the desired mode:
    • 0: Disable Game Filter
    • 1: Enable TCP and UDP (full coverage)
    • 2: Enable TCP only
    • 3: Enable UDP only (optimal for most games)
  3. Confirm the selection to write the flag to utils\game_filter.enabled
  4. Restart the Zapret service to apply the new port filters

Technical Configuration Examples

Manual configuration follows the same variable substitution pattern used by the automated installer. Setting the full Game Filter mode requires defining the environment variables before service creation:

:: Enable full TCP and UDP filtering
set "GameFilter=1024-65535"
set "GameFilterTCP=1024-65535" 
set "GameFilterUDP=1024-65535"

:: Build argument string with placeholders replaced
set "ARGS=--port=%GameFilter% --tcp-port=%GameFilterTCP% --udp-port=%GameFilterUDP%"

:: Create and start the service
sc create zapret binPath= "\"%~dp0bin\winws.exe\" %ARGS%" start= auto
sc start zapret

The flag file contents correspond directly to menu selections:

:: TCP and UDP mode
all

:: UDP only mode  
udp

:: TCP only mode
tcp

Summary

  • Game Filter redirects high-port traffic (1024-65535) through WinDivert by configuring winws.exe with dynamic port-range arguments injected via service.bat.
  • The mode persists configurations in utils\game_filter.enabled, supporting three operational states: TCP only, UDP only, or both protocols simultaneously.
  • Bypass occurs at the packet level: WinDivert intercepts raw traffic before Windows processes it, preventing DPI systems from analyzing game data flows.
  • Most effective for UDP-based games that utilize dynamic high ports rather than standard HTTP/HTTPS channels.

Frequently Asked Questions

What port ranges does Game Filter mode affect?

Game Filter captures all traffic on ports 1024 through 65535, covering the entire ephemeral port range used by modern multiplayer games and peer-to-peer applications. Standard service ports (0-1023) remain unaffected, ensuring system stability while gaming traffic receives DPI bypass treatment.

Why is Game Filter more effective for games than standard bypass modes?

Traditional DPI concentrates inspection efforts on well-known ports like 80 and 443, while many games utilize dynamic high ports and UDP protocol for real-time communication. Game Filter specifically targets these overlooked traffic patterns by forcing WinDivert to intercept packets on the exact ports games actually use, creating a tunnel that circumvents shallow packet inspection techniques.

How do I completely disable Game Filter after enabling it?

Navigate to service.bat and select 4. Game Filter, then choose option 0 to disable. This removes the port range arguments from the service configuration during the next restart. Alternatively, delete the utils\game_filter.enabled flag file manually and restart the Zapret service to return to standard filtering behavior.

Does Game Filter impact system performance or other applications?

Because Game Filter captures traffic across the entire high-port spectrum (1024-65535), it may intercept non-gaming applications that utilize these ports, such as voice chat software or torrent clients. The performance impact remains minimal due to WinDivert's kernel-level efficiency, but users may notice the bypass affecting traffic characteristics for any application using high-numbered ports while the mode is active.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →